Review a false ban

Which detections you can act on immediately, which need the evidence read first, and how to tell them apart.

Use the log evidence before you act. Start with the Additional Info panel, which names the detection and the value that fired it, then open any screenshot or recording attached to the ban. For most detections that is enough to tell real cheating from a false positive in under a minute.

Detections you can usually act on

These fire on something the server can prove: a value the game cannot produce, an exact match against a list you control, or a request a normal client never sends. A hit here is almost always the player, though the evidence is still worth a look when the punishment is permanent.

DetectionWhy it is hard to fire by accident
AntiAimbotNeeds aim behaviour no human input produces.
AntiSilentAimA hit registered while the weapon was never pointed at the target.
AntiMagicBulletA hit with no trajectory between the muzzle and the target.
AntiGiveWeaponsA weapon appearing in an inventory the server never put it in.
AntiRemoveWeaponsA weapon leaving an inventory the server did not take it from.
AntiStartResourcesA client asking the server to start a resource.
AntiStopResourcesA client asking the server to stop a resource.
AntiSpoofBulletShotShot data that contradicts what the game reported.
AntiBlacklistWeaponsAn exact match against a list you control.
BlacklistEntitiesProtectionAn exact model match against a list you control.
AntiSpawnIsolatedVehicleA vehicle created outside any normal spawn path.
AntiDamageExploitsDamage values the game cannot produce.
AntiSpoofedDamageDamage attributed to a weapon that did not fire it.

Detections to read the evidence on first

These are not unreliable, but their trigger can also be produced by your own scripts, a weak machine or a bad connection. Read the evidence and the Additional Info before you punish, and when one of them fires repeatedly on ordinary players, treat that as a config problem rather than a cheating problem.

DetectionWhat the innocent explanation looks like
ClipboardScannerMatches its word list as a substring, so ordinary words hit. "sprint" contains "print".
AntiScreenOcrReads text off the screen, including text your own UI drew. Ships off for this reason.
AntiExecutorOverlays and capture tools can look like an injector. Check the evidence before acting.
AntiNuiTamperThe Timeout half fires when the browser layer hangs, which a weak machine does on its own.
AntiGodmodeTests by dealing one damage and watching. Health scripts that heal instantly look identical.
AntiSpawnWeaponsAny custom weapon you have not registered reads as an unknown weapon appearing.
AntiSpeedHackSprint modifiers, parkour scripts and vehicle ejection all produce real speed.
AntiNoclipFalling through unloaded map geometry looks the same as walking through it.
AntiTeleportInVehicleGarage scripts and vehicle resets move a player instantly on purpose.
AntiParticleAiScripted effects on a busy scene can cross the spam rules without anyone cheating.
AntiExplosionAiScripted explosions in a job or an event can cross the spam rules the same way.
AiServerEventsProtectionThe highest false-positive surface on any framework server. Read the event name first.
EntitiesSpamProtectionAn inventory dropping a large stash, or a garage pulling several cars, counts as spam.
AntiResourcesInjectionOn a resource older than 1.8.5.8, ox_lib triggers this legitimately. Update before trusting it.

If you decide it was a false positive

Lift the ban from the Bans List, then fix the cause so it does not happen to the next player. The Additional Info panel almost always names something you can whitelist: the resource that created an entity, the event that was blocked, the model, or the weapon. Whitelisting that one thing is better than raising a threshold, because a threshold change weakens the detection for everybody.